DocumentCode :
2847519
Title :
A Novel Security Scheme for Online Banking Based on Virtual Machine
Author :
Guan, Bei ; Wu, Yanjun ; Wang, Yongji
fYear :
2012
fDate :
20-22 June 2012
Firstpage :
12
Lastpage :
17
Abstract :
Current online banking scheme built on ordinary software stack, which comprises of the operating system and its applications running on it, is facing attacks including Phishing, Pharming, Malicious Software Attacks (MSW), Man in the Middle Attacks (MITM) and Key logger. Today´s countermeasures either prevent only part of these attacks or have high cost on performance and usability. In this paper, we introduce the Domain Online Banking (DOBank), a novel security scheme for online banking that combines the virtual machine (VM) technology with web services. Firstly, DOBank encapsulates the banking service into a lightweight domain and protects it from any attacks caused by virus from the user´s host. Secondly, the domain can access certain hardware devices exclusively against Key logger and gains nearly native performance using the pass through technology. Finally, we use the virtual Trusted Platform Module (vTPM) for the online banking domain´s integrity verification as well as the SSL/TLS (Security Sockets Layer/Transport Layer Security) protocol for the confidentiality of data transaction over the internet. We show that this scheme is secure enough to prevent typical viruses that threaten the online banking. The experiments on the network throughput and the time consumed of integrity measurement show it adds little overhead to the overall system.
Keywords :
Browsers; Internet; Online banking; Runtime environment; Security; Servers; Software; online banking; security; virtual machine; virtualization; web service; xen;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Software Security and Reliability Companion (SERE-C), 2012 IEEE Sixth International Conference on
Conference_Location :
Gaithersburg, MD, USA
Print_ISBN :
978-1-4673-2670-4
Type :
conf
DOI :
10.1109/SERE-C.2012.28
Filename :
6258439
Link To Document :
بازگشت